WP Contact Form is a very popular WordPress plugin.
Mustlive has reported a number of vulnerabilities which you can view at his web page here.
According to the plugin authors page, the latest version is 3.1.8. We went ahead and downloaded a copy to have a look. The actual contact form page that your users see is not vulnerable to these attacks. However, the "/wp-admin/admin.php?page=wp-contact-form
/options-contactform.php" is vulnerable.
Please note at the time of writing this article all versions appear affected (<=3.1.8). We recommend disabling this plugin until a fix can be provided.